• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Need to secure Plesk 12.0.18 on Ubuntu 14.04 VPS

cartj

New Pleskian
Dear all,
after googleing three days and reading much KBs and tutorials/workarounds I'm still stuck and would like to ask for some help.
I'm new to plesk and need to secure a VPS runnig plesk for one of our clients because his admin has quit.
There are some domains hosted on the server, it is runnig apache as webserver and I'm currently trying to disable SSLv3 and weak Ciphers so I've first tried:

http://download1.parallels.com/Ples...compliance-guide/index.htm?fileName=65871.htm

Disabling weak SSL ciphers and protocols
/usr/local/psa/admin/bin/pci_compliance_resolver --enable all
service apache2 restart

this did not change anything on sitechecks like https://www.tinfoilsecurity.com/poodle or https://www.ssllabs.com/ssltest/

so I've tried to update the ciphers in
/etc/sw-cp-server/conf.d/pci-compliance.conf
and restarted apache but without any visible results.

I think this patch relies to ngix webserver, I'm using apache

so I've searched for apache configs and found a reccommendation to edit
/etc/apache2/mods-available/ssl.conf and changing the values:

SSLCipherSuite RC4-SHA:AES128-SHA:HIGH:MEDIUM:!aNULL:!MD5!:!RC4
SSLHonorCipherOrder on

SSLProtocol All -SSLv2 -SSLv3


service apache2 restart

but this had also no effect, I still got the message that SSLv3 is still enabled.

Is anybody runnig a similar setup so that you could provide info where I should edit files to make sure they're recognized by Plesk?

Do I still need to patch ngix even if I don't use it?

Thank you very much for reading (I know that there aresome threads in this board and others but I've currently nothing found that works) and your help.
 
can be closed, sorry for bothering, did download the script and everything is fine now, don't know how to delete the topic.
 
Back
Top